PT-2026-75987 · Packagist · Winter/Wn-Backend-Module
Publicado
2026-08-12
·
Atualizado
2026-08-12
CVSS v3.1
5.9
Média
| Vetor | AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:N |
Impact
The Backend Filter widget (
BackendWidgetsFilter) is vulnerable to SQL injection through the numberrange scope type when the scope is configured with a conditions key. An authenticated backend user with access to a list view containing a vulnerable filter scope can inject arbitrary SQL via the filter's AJAX handler, potentially gaining read access to the full database contents.To exploit this, an attacker must have a valid backend account with access to a list view where a third-party plugin has registered a
numberrange filter scope using the conditions configuration key. No built-in Winter CMS backend views use this scope type and configuration combination, so a vanilla installation without plugins is not exploitable.Patches
This issue has been fixed in Winter CMS v1.2.13.
Workarounds
If users cannot upgrade, they may apply commit https://github.com/wintercms/winter/commit/50713de95adf5298536d93f4d999652525d36d43 to your Winter CMS
installation manually to resolve this issue.
Correção
SQL injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Winter/Wn-Backend-Module